Security
What we do with your data — and the boundaries we set on agents.
This page covers data handling and the operating boundaries of our agents. For the full legal terms, see the Privacy Policy.
Your data
Legal basis — we process personal data under Indonesia's Law No. 27 of 2022 on Personal Data Protection.
Minimisation — we collect only what is needed to answer your enquiry and to carry out agreed work.
Encryption — data is encrypted in transit.
Access control — access is limited to the people who need it.
Third-party processors — only service providers that help us run the business, contractually bound to protect the data.
For client work — storage location, retention period and deletion procedure are agreed in writing before the engagement begins.
The boundaries we set on agents
Scope — what work it may do, and what falls outside it.
Data access — which sources it may read. No access is granted without a written reason.
Actions — what it may do without human approval, and what it may not.
Review point — at which step the accountable person checks before the result moves on.
Escalation — what happens when the agent meets a case outside its boundary.
Trail — what is recorded so decisions can be reviewed later.
What we do not have
We do not hold third-party security certifications such as ISO 27001 or SOC 2, and we do not claim otherwise. We also do not promise Indonesian data residency as standard — if that is a requirement, say so early and we will agree it in writing before work begins.
Not sure which one fits?
Start with a diagnostic conversation. If none of the three is a good fit, we will tell you.